VDB
KO
LOW

GHSA-4g5m-c9r5-49xf

LiteLLM: Local file read via request-supplied OIDC file references

Quick fix

GHSA-4g5m-c9r5-49xf — litellm: upgrade to the fixed version with the command below.

pip install --upgrade 'litellm>=1.83.10'

Details

### Impact

LiteLLM's `/health/test_connection` endpoint resolved request-supplied environment and OIDC file references in `litellm_params`. A proxy administrator, or another privileged caller with permission to test model connections, could cause LiteLLM to read files from the local filesystem via an `oidc/file/` reference.

Because exploitation requires privileged proxy access, this is treated as a defense-in-depth issue rather than a cross-tenant privilege bypass.

### Patches

The issue is fixed in `1.83.10-stable`.

LiteLLM recommend upgrading to `1.83.10-stable` or later.

### Workarounds

Restrict `/health/test_connection` access to trusted administrators only.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / litellm
Introduced in: 0 Fixed in: 1.83.10
Fix pip install --upgrade 'litellm>=1.83.10'

References